> ## Documentation Index
> Fetch the complete documentation index at: https://security.tryswell.co/llms.txt
> Use this file to discover all available pages before exploring further.

# No SOC 2 Yet

> Compensating controls in place while Swell pursues SOC 2 certification.

**Last updated:** July 27, 2026

San Gregorio Labs Inc. (Swell) doesn't hold SOC 2 Type II or ISO 27001 certification. No committed date: we're early-stage, and a 6-12 month audit engagement isn't the right investment yet. Here's what governs your data in the meantime.

## Compensating controls

| Area                   | What's in place                                                                                                                                                                                                                                                                                            |
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Subprocessor certs** | Deepgram (SOC 2 certified), WorkOS (SOC 2 Type II certified). OpenAI and Anthropic: enterprise API terms, no training on customer content by default.                                                                                                                                                      |
| **Retention**          | No raw audio stored, ever. Transcripts and coaching suggestions auto-purged 24 hours after creation (hourly cron). Abandoned sessions purged on the same schedule.                                                                                                                                         |
| **LLM data handling**  | `zeroDataRetention: true` on every Anthropic request (via Vercel AI Gateway). OpenAI Realtime doesn't train on API content by default; standard accounts may hold abuse-monitoring logs up to 30 days, a platform-level safeguard, not something we control or opt into.                                   |
| **Encryption**         | TLS 1.2+ in transit. Encryption at rest via Convex/cloud provider defaults. Auth tokens in macOS Keychain only.                                                                                                                                                                                            |
| **Access control**     | One founder-engineer, no other employees. Sole access to Convex, Vercel, and Railway; MFA enforced on all four platforms (incl. WorkOS). No shared logins, no standing service accounts. Formal access policy (documented list, no over-provisioning) goes in before the first hire gets prod credentials. |

## Bottom line

Not a SOC 2 substitute, but a real, verifiable account of current controls. Need our DPA? See the [DPA page](/dpa) or [download the PDF](https://www.tryswell.co/swell-dpa-external/swell_dpa_external.pdf). Ready now. Need a completed security questionnaire? [hello@tryswell.co](mailto:hello@tryswell.co).

Questions not covered here: [hello@tryswell.co](mailto:hello@tryswell.co) or the [Security Overview](/).
